Jump to content
YOUR-AD-HERE
HOSTING
TOOLS

Locked Wifiphisher


0wner

Recommended Posts

[h=2]About[/h]

This is the hidden content, please
is a security tool that performs Wi-Fi automatic association attacks to force wireless clients to unknowingly connect to an attacker-controlled Access Point. It is a rogue Access Point framework that can be used to mount automated victim-customized phishing attacks against WiFi clients in order to obtain credentials or infect the victims with malwares. It can work a social engineering attack tool that unlike other methods it does not include any brute forcing. It is an easy way for obtaining credentials from captive portals and third party login pages (e.g. in social networks) or WPA/WPA2 pre-shared keys.

 

Wifiphisher works on Kali Linux and is licensed under the GPL license. [h=2]

How it works[/h]

After achieving a man-in-the-middle position using Wi-Fi automatic association techniques (including "KARMA" and "Known Beacons" attacks), Wifiphisher by default redirects all HTTP requests to an attacker-controlled phishing page.

 

From the victim's perspective, the attack makes use in three phases:

  1. Victim is being deauthenticated from her access point. Wifiphisher continuously jams all of the target access point's wifi devices within range by forging “Deauthenticate” or “Disassociate” packets to disrupt existing associations.
  2. Victim joins a rogue access point. Wifiphisher sniffs the area and copies the target access point's settings. It then creates a rogue wireless access point that is modeled by the target. It also sets up a NAT/DHCP server and forwards the right ports. Consequently, because of the deauth attack and the automatic association techniques, clients will eventually start connecting to the rogue access point. After this phase, the victim is MiTMed.
  3. Victim is being served a realistic specially-customized phishing page. Wifiphisher employs a minimal web server that responds to HTTP & HTTPS requests. As soon as the victim requests a page from the Internet, wifiphisher will respond with a realistic fake page that asks for credentials or serves malwares. This page will be specifically crafted for the victim. For example, a router config-looking page will contain the brand of the victim's vendor. The tool supports community-built templates for different phishing scenarios.

[h=2]Requirements[/h]

Following are the requirements for getting the most out of Wifiphisher:

  • Kali Linux. Although people have made Wifiphisher work on other distros, Kali Linux is the officially supported distribution, thus all new features are primarily tested on this platform.
  • One wireless network adapter that supports AP & Monitor mode and is capable of injection. For advanced mode, you need two cards; one that supports AP mode and another that supports Monitor mode. Drivers should support netlink.

[h=2]Installation[/h]

To install the latest development version type the following commands:

 

git clone

This is the hidden content, please
# Download the latest revision cd wifiphisher # Switch to tool's directory sudo python setup.py install # Install any dependencies

 

 

DOWNLOAD

Link to comment
Share on other sites

This is tool gets the job done

 

-From Using successfully plenty of times On different Businesses-

 

1 - Take laptop + Proper WifiAdapter (InjectPackets capability)

2 - Pull up to your local Cell-Phone repair shops. ( Make sure they activate phones there)

3 - I usually have it on terminal with command set # wifiphisher -jI -aI -e

Leave It running in-range.(In car close as possible)

4 - [light_Soc.Eng. -> "Choose any service as if you are going to activate it, easiest/fastest one to setup = best-option]

They will be unable to as they require signing in to a website provided by carrier.....And you get the plain text Psswd.

**Bonus**

You can now fuck all devices on wifi connected, I personally drop a rat/meterpreter/ through JS payloads hitting every browser

accessed by that wifi connection. You should end up with access to their main pc...

usually find some CC's + unlimited service as long as you keep it lokey...access to merchant gateway (...make this next target)

-Best method for fresh disposable burner sims/phones-

 

 

# Usually these shops run windows, this should help when you get shell access -

This is the hidden content, please

 

 

 

[email protected]

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.